Hundreds of thousands of FortiGate firewalls are vulnerable to a critical security issue identified as CVE-2023-27997, nearly a month after Fortinet released an update that addressed the issue.
See also: The construction sector is exposed to many ransomware attacks

The vulnerability is a remote code execution vulnerability with a severity rating of 9.8 out of 10, resulting from a heap-based buffer overflow issue in FortiOS – the operating system that connects all of Fortinet's networking components for integration into the vendor's Security Fabric platform.
See also: Europol: Authorities arrested gang members who were defrauding elderly people
CVE-2023-27997 is exploitable and allows an unauthorized attacker to execute code remotely on vulnerable devices with the SSL VPN interface exposed to the internet. In an advisory in mid-June, the vendor warned that the issue could have been exploited in attacks.
On June 11, Fortinet addressed the vulnerability by releasing FortiOS firmware versions 6.0.17, 6.2.15, 6.4.13, 7.0.12, and 7.2.5 before publicly disclosing it.
Offensive security solutions company Bishop Fox reported on Friday that, despite calls for a fix, more than 300,000 FortiGate firewall devices are still vulnerable to attack and remain accessible via the public internet.
Bishop Fox researchers used the Shodan search engine to find devices that responded in a way that suggested an exposed SSL VPN interface, by searching for devices that returned a specific HTTP response header.
They filtered the results to those that redirected to “/remote/login,” a clear indication of an exposed SSL VPN interface.
The above query showed 489,337 devices, but not all of them were vulnerable to CVE-2023-27997, also referred to as Xortigate. Upon further investigation, the researchers discovered that 153,414 of the discovered devices had been updated to a secure version of FortiOS.

See also: WordPress plugin gives hackers admin access to your site
This means that about 335,900 of the FortiGate firewalls accessible via the internet are vulnerable to attack—a number significantly higher than the recent estimate of 250,000 based on other, less precise queries, say the Bishop Fox researchers.
Bishop Fox researchers also discovered that many of the exposed FortiGate devices had not received updates in the past eight years, while some were running FortiOS 6, which reached the end of support last year on September 29.
These devices are vulnerable to several critical flaws for which proof-of-concept exploit code is publicly available.
To demonstrate that CVE-2023-27997 can be used to remotely execute code on vulnerable devices, Bishop Fox created an exploit that “crashes the heap, connects to an attacker-controlled server, downloads a BusyBox binary, and opens an interactive shell.”
Information source: bleepingcomputer.com
